Impact assessment
Material impacts on users, workers, customers or the public are assessed.
The FTC alleged Rite Aid deployed AI-based facial recognition without reasonable safeguards and that the system generated thousands of false-positive matches, with disproportionate risks in some communities.
Rite Aid agreed to a five-year prohibition on using facial recognition for surveillance purposes and other safeguards, subject to court approval processes described by the FTC.
The FTC alleged insufficient accuracy testing, risk assessment, consumer notice, vendor oversight and data-security controls.
Five-year surveillance ban, comprehensive safeguards, information-security programme and oversight requirements.
This record should inform control design, testing and monitoring for comparable AI systems. The incident database does not infer that every system using the same provider or model shares the same failure.
These are CRG methodology mappings from the documented incident to controls worth testing in comparable systems. They do not assert that any single control would have prevented the incident.
Material impacts on users, workers, customers or the public are assessed.
Personal, confidential and regulated data is protected in AI workflows.
Relevant privacy rights and deletion/correction processes extend to AI-enabled processing.
Materially affected groups and differential risks are identified.
Where relevant, outcome disparities are measured using appropriate metrics.
U.S. Federal Trade Commission · confidence 99% · last verified 23 Aug 2026
Open underlying source